Azure安全默认值启用疑问及Power BI Embedded认证影响咨询
关于Security Defaults启用的疑问及服务主体认证代码说明
问题背景
作为租户管理员,登录Outlook、Power BI或Azure时,持续收到弹窗提示组织将在2天后自动启用Security Defaults,无直接关闭选项,但当前已在Azure的MS Entra中禁用该功能。有以下两个疑问:
- 自动启用后能否再次关闭?
- 当前使用主账户生成访问令牌调用Power BI Embedded APIs/SDK,启用Security Defaults后是否会受影响?
另外计划将代码改为服务主体认证,以下是原代码与修改后代码:
原代码(用户名密码认证)
IPublicClientApplication clientApp = PublicClientApplicationBuilder .Create(ConfigValidatorService.ApplicationId) .WithAuthority(m_authorityUrl) .Build(); var userAccounts = await clientApp.GetAccountsAsync(); SecureString secureStringPassword = new SecureString(); foreach (var key in ConfigValidatorService.Password) { secureStringPassword.AppendChar(key); } AuthenticationResult authenticationResult = await clientApp.AcquireTokenByUsernamePassword(m_scope, ConfigValidatorService.Username, secureStringPassword).ExecuteAsync();
修改后代码(服务主体认证)
IConfidentialClientApplication clientApp = ConfidentialClientApplicationBuilder .Create(ConfigValidatorService.ApplicationId) .WithClientSecret(ConfigValidatorService.ApplicationSecret) .WithAuthority(tenantSpecificURL) .Build(); var authenticationResult = await clientApp.AcquireTokenForClient(m_scope).ExecuteAsync();
解答
1. 自动启用后能否再次关闭?
可以。即便Security Defaults被自动启用,租户管理员仍可在MS Entra管理中心手动关闭该功能。但需注意:如果租户未配置其他符合要求的条件访问策略,关闭后可能再次收到启用提示,建议同步配置自定义条件访问规则替代Security Defaults的安全防护。
2. 启用Security Defaults对当前主账户调用Power BI Embedded APIs的影响
会产生影响。Security Defaults启用后,用户名密码认证(ROPC)方式会被禁用,而当前代码正是采用该方式获取令牌,这会导致调用Power BI Embedded APIs/SDK时认证失败,无法获取有效令牌。
服务主体认证代码说明
你修改后的服务主体认证代码方向正确,Security Defaults启用后不会影响该认证方式(只要服务主体权限配置正确)。需注意以下几点:
- 确保服务主体已被授予Power BI Embedded所需权限(比如在Power BI管理门户中添加服务主体为工作区管理员,或分配对应应用权限)
tenantSpecificURL需替换为租户专属权威URL,格式通常为https://login.microsoftonline.com/{tenant-id}- 建议不要直接硬编码客户端密钥,可使用Azure Key Vault等安全方式存储和获取密钥
内容的提问来源于stack exchange,提问作者CSharp
相关产品推荐
相关产品推荐

